CVE-2010-0213

Publication date 28 July 2010

Last updated 24 July 2024


Ubuntu priority

BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of service (infinite loop) via a query for an RRSIG record whose answer is not in the cache, which causes BIND to repeatedly send RRSIG queries to the authoritative servers.

Read the notes from the security team

Status

Package Ubuntu Release Status
bind9 10.04 LTS lucid
Not affected
9.10 karmic
Not affected
9.04 jaunty
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected

Notes


sbeattie

only affects 9.7.1 and 9.7.1-P1, earlier versions okay.